# Remote BIOS Password Management with Hexnode

**TL;DR:** Remotely configure, update, or remove BIOS and pre-boot System passwords on Windows devices directly from **Actions > Security**. Configured credentials can be securely retrieved in masked format under **Device Info > Device Status Info**.

Executive Summary
-----------------

Configuring firmware security traditionally requires manual, desk-side IT visits. Hexnode UEM eliminates this operational overhead by bringing remote hardware-level password management directly to the console. Admins can restrict firmware access or lock endpoints at the pre-boot level before the OS loads.

OEM Compatibility Matrix
------------------------

Remote ActionSupported Device Manufacturers**BIOS Password Actions**

- Set
- Change
- Clear

ASUS, HP, Dell, Lenovo**Set System Password**Dell**Change / Clear System Password**Dell, LenovoHow to configure BIOS & System password actions?
----------------------------------------------------

1. Login to Hexnode UEM portal.
2. Navigate to **Manage > Devices**.
3. Select the Windows device you want to Set/Change/Clear BIOS/System password.
4. Go to **Actions > Security**.

How to set BIOS password?
-------------------------

**What is Set BIOS Password action?**

The **Set BIOS Password** action configures a new password on the target Windows device to protect and lock the BIOS firmware settings.

**Why use this action?**

This action prevents users or unauthorized individuals from tampering with low-level hardware configurations—such as altering the boot order to boot from untrusted USB drives, disabling Secure Boot, or bypassing OS security controls. Essential during initial device onboarding or when sending devices to remote/field employees.

**How to execute:**

- **Action:** Select **Set BIOS Password**.
- **Required Inputs:** Enter the password and click **Done**.

How to change BIOS password? 
-----------------------------

**What is Change BIOS Password action?**

The **Change BIOS Password** action updates an existing BIOS password on the device to a new credential.

**Why use this action?**

This action allows admins to routinely update BIOS credentials, respond to IT staff turnover, or update credentials if an active BIOS password has been shared or exposed during physical maintenance.

**How to execute:**

- **Action:** Select **Change BIOS Password**.
- **Required Inputs:** Enter the **Current password** and **New password**, then click **Done**. Passwords cannot begin or end with spaces.

How to clear BIOS password? 
----------------------------

**What is Clear BIOS Password action?**

The **Clear BIOS Password** action removes password protection from the device’s BIOS settings completely.

**Why use this action?**

This action is needed when offboarding endpoints, sending hardware to third-party repair vendors, returning leased equipment, or reassigning devices to teams that require open access to BIOS configurations.

**How to execute:**

- **Action:** Select **Clear BIOS Password**.
- **Required Inputs:** Enter the **Current password** and click **Clear Password**.

How to set system password? 
----------------------------

**What is Set System Password action?**

The **Set System Password** action configures a pre-boot hardware password that locks the device before the operating system even begins to load.

**Why use this action?**

This action is ideal when deploying laptops to field employees or remote staff handling sensitive data. It ensures that if a device is physically lost or stolen, no one can boot the machine, access internal storage, or bypass security using external bootable drives.

**How to execute:**

- **Action:** Select **Set System Password**.
- **Required Inputs:** Enter the password and click **Done**.

How to change system password? 
-------------------------------

**What is Change System Password action?**

The **Change System Password** action updates the existing pre-boot system password with a new credential.

**Why use this action?**

This action is useful when rotating pre-boot security keys, reassigning a pre-boot locked device to a new user, or updating credentials after a potential security leak without removing hardware protection entirely.

**How to execute:**

- **Action:** Select **Change System Password**.
- **Required Inputs:** Enter the **Current password** and **New password**, then click **Done**. Passwords cannot begin or end with spaces.

How to clear system password? 
------------------------------

**What is Clear System Password action?**

The **Clear System Password** action completely removes the pre-boot hardware password from the device.

**Why use this action?**

This action is required when transitioning a device back to standard OS-only login, sending devices for OEM vendor hardware repairs, or preparing endpoints for fleet re-imaging.

**How to execute:**

- **Action:** Select **Clear System Password**.
- **Required Inputs:** Enter the **Current password** and click **Clear Password**.

View BIOS & System Password
-------------------------------

The configured or updated BIOS and System passwords can be viewed by navigating to: **Manage > Devices > select the target device > Device Info tab > Device Status Info section**. Click the eye icon toggle to reveal the password.

This provides authorized IT administrators with a secure, centralized location to retrieve active hardware credentials. It serves as a critical safeguard during on-site hardware maintenance, device reassignments, or troubleshooting, allowing admins to instantly recover credentials if local passwords are forgotten or lost to prevent device lockouts.